The store's map_err(|_| Internal) discarded the real IO error, so a disk-full or permissions failure was invisible; log it once in the log append path where it happens. Add echo_api::require_oper (parameterised by the required privilege) and route the three copied per-service guards through it, keeping each service's own wording and policy. |
||
|---|---|---|
| .. | ||
| src | ||
| templates/email | ||
| Cargo.toml | ||